CVE-2016-8503: High severity yandex browser vulnerability
Published Oct 26, 2016
·Updated
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
Affected Software
3 affected components
Yandex Yandex Browser=16.7.0.3342
Yandex Yandex Browser=16.7.1.20808
Yandex Yandex Browser=16.9.1.1131
Event History
Oct 26, 2016
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-8503?
CVE-2016-8503 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-8503?
The best way to fix CVE-2016-8503 is to update Yandex Browser to version 16.10 or later.
3
What type of attacks does CVE-2016-8503 allow?
CVE-2016-8503 may allow remote attackers to perform brute-force password attacks on important web resources.
4
Which versions of Yandex Browser are affected by CVE-2016-8503?
CVE-2016-8503 affects Yandex Browser versions 16.7.0.3342, 16.7.1.20808, and 16.9.1.1131.
5
Is there a workaround for CVE-2016-8503?
There is no specific workaround for CVE-2016-8503, so upgrading is strongly recommended.